Saltar al contenido
Lankoa

Privacy Policy

Who processes your data

  • Controller: (to be completed)
  • Tax ID: (pending)
  • Address: (pending)
  • Email: (pending)
  • Data protection officer: None appointed, as it is not mandatory for this activity.

What data we process and where it comes from

We only process data you give us yourself, and only what is needed for what you ask of us:

  • Contact form: name, email address, subject and the content of your message.
  • Technical data: anonymised IP address, date and time, and the page from which the form is sent or cookie consent is recorded.
  • Email correspondence: whatever data you include when writing to us.

We do not buy databases and we do not obtain your data from third parties. We do not carry out profiling or automated decision-making that affects you.

What we use it for and on what legal basis

  • Answering your enquiry. Legal basis: your consent (art. 6.1.a GDPR), given by ticking the box on the form, and pre-contractual steps taken at your request (art. 6.1.b GDPR).
  • Managing the professional relationship if we end up working together. Legal basis: performance of a contract (art. 6.1.b GDPR).
  • Meeting legal obligations regarding tax, accounting and data protection. Legal basis: legal obligation (art. 6.1.c GDPR).
  • Keeping the site secure and preventing form abuse. Legal basis: legitimate interest (art. 6.1.f GDPR), limited to technical data with the IP anonymised.
  • Evidencing cookie consent. Legal basis: legal obligation under article 22.2 LSSI and the GDPR accountability principle.

We do not use your data to send you marketing communications unless you expressly and separately ask us to.

How long we keep it

  • Enquiries that do not lead to a professional relationship: one year from the last contact, then deleted.
  • Professional relationship: for its duration and afterwards for the applicable limitation periods (generally six years for commercial matters and four for tax matters under Spanish law).
  • Cookie consent records: while the consent is valid and for up to three years afterwards, so that it can be evidenced.

Who we share it with

We do not pass your data to third parties except where legally required. It is accessed, as processors and under a contract compliant with article 28 GDPR, by the providers needed for the service to work:

  • Web hosting and email: (provider to be specified).
  • Tax and accounting advisers, where invoicing is involved.

Servers in the European Union: (to be confirmed). Should an international transfer ever be necessary, it would be carried out with the safeguards in Chapter V of the GDPR and reported on this page.

Your rights

You may exercise the following rights at any time:

  • Access: find out what data of yours we process.
  • Rectification: correct data that is inaccurate or incomplete.
  • Erasure: ask us to delete it when it is no longer needed.
  • Objection: object to processing based on our legitimate interest.
  • Restriction: ask us to keep it but not use it while a claim is resolved.
  • Portability: receive your data in a structured, commonly used format.
  • Withdraw consent at any time, without affecting the lawfulness of earlier processing.

To exercise them, write to (pending) stating which right you wish to exercise. We will reply within one month. We may ask you to prove your identity, purely to make sure we do not hand your data to someone else.

Complaints to the supervisory authority

If you believe we have not handled your request properly, you may complain to the Spanish Data Protection Agency (C/ Jorge Juan, 6, 28001 Madrid — www.aepd.es). We would appreciate the chance to put things right first.

Security

We apply technical and organisational measures appropriate to the risk: encrypted HTTPS connection, administrator access limited to authorised people, regular backups and minimisation of the data we collect. IP addresses are always stored anonymised.

Should a security breach occur that poses a risk to your rights, we would inform you and notify the Spanish Data Protection Agency within the deadlines set by the GDPR.

Children

This site is not aimed at children under 14 and we do not knowingly collect their data. If we find we have received a minor’s data without the consent of their guardian, we will delete it.

Changes to this policy

We may update this policy to reflect legal changes or new processing activities. The version in force is the one published on this page; if a change were substantial, we would flag it clearly.


Last updated: the modification date shown for this page.